First published: Fri Feb 04 2022(Updated: )
CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a vulnerability in the CSV export functionality, due to insufficient input validation, that can allow a privileged user to potentially execute arbitrary code or commands.
Credit: vuln@ca.com
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom CA Harvest Software Change Manager | =13.0.3 | |
Broadcom CA Harvest Software Change Manager | =13.0.4 | |
Broadcom CA Harvest Software Change Manager | =14.0.0 | |
Broadcom CA Harvest Software Change Manager | =14.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22689 is classified as a critical vulnerability due to its potential for allowing arbitrary code execution.
To mitigate CVE-2022-22689, update CA Harvest Software Change Manager to version 14.0.2 or later.
CVE-2022-22689 affects CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1.
The vulnerability in CVE-2022-22689 involves insufficient input validation in the CSV export functionality.
Currently, the recommended action for CVE-2022-22689 is to upgrade to the fixed version as no specific workarounds have been provided.